{
  "coverSheet": "REDOUBT VAULT \u2014 CONSENT EVIDENCE PACKET\nExport exp_01a11456e93a788296368e51563e481f, generated 2026-10-07 03:10:02 UTC.\nAccount: Redoubt Vault (northline). The name is the account owner\u0027s; the id is Redoubt Vault\u0027s and never changes.\nScope: every consent event recorded for recipient \u0027riley.okonkwo@sample-buyer.example\u0027 under tenant \u0027sample-dealership\u0027, as of the generation time above.\nIt holds 2 consent events for 1 person, 1 wording revision and 0 unsubscribes.\nOf its 2 consent events, 2 were reported as they happened, 0 were reported late, and 0 were imported from the platform\u0027s own records.\nEach event opens with a summary in plain words and the wording the person agreed to.\nNothing outside the scope was queried, and this packet does not attest to anything it does not contain.\nHow to read every section is at the end of this packet, under howToRead.\n",
  "manifest": {
    "formatVersion": "15",
    "exportId": "exp_01a11456e93a788296368e51563e481f",
    "generatedAt": "2026-10-07T03:10:02.4400203Z",
    "account": {
      "platformId": "northline",
      "name": "Redoubt Vault"
    },
    "tenantId": "sample-dealership",
    "recipientFilter": "riley.okonkwo@sample-buyer.example",
    "eventCount": 2,
    "peopleCount": 1,
    "eventsWithTermsCaptured": 2,
    "eventsWithoutTermsCaptured": 0,
    "eventsNamingWhoPermissionRanTo": 2,
    "eventsNotNamingWhoPermissionRanTo": 0,
    "eventsReportedAsTheyHappened": 2,
    "eventsReportedLate": 0,
    "eventsThePlatformImported": 0,
    "eventsWhereThisWasNeverRecorded": 0,
    "suppressionCount": 0,
    "recipientsUnsubscribed": 0,
    "eventsConfirmingASignupWeHold": 2,
    "eventsNamingNoSignupRequest": 0,
    "termsRevisionsEmbedded": 1,
    "recipientErasedOnRequestAt": [],
    "eventsWhosePersonWasErased": 0,
    "coverage": "every consent event recorded for recipient \u0027riley.okonkwo@sample-buyer.example\u0027 under tenant \u0027sample-dealership\u0027, as recorded up to 2026-10-07T03:10:02.4400203Z"
  },
  "suppressions": [],
  "consentTerms": [
    {
      "termsId": "trm_2cacea7fb8c12c058201e75322523b2692f8ead16b8cde184e8a12ec4dfc849c",
      "contentType": "text/plain",
      "sizeBytes": 110,
      "heldSince_observedByRedoubtVault": "2026-09-14T00:38:06.6991471Z",
      "documents": [
        {
          "name": "sample-newsletter-opt-in-dealership-only",
          "revision": 1,
          "revisionsOnRecord": 1,
          "recordedAt": "2026-09-14T00:38:06.6991471Z",
          "supersededAt": "not superseded \u2014 this is the current revision",
          "postedAtUrl_assertedByPlatform": "https://sample-dealership.example/newsletter",
          "postedAt_assertedByPlatform": "2026-09-01T09:00:00.0000000Z"
        }
      ],
      "content": "Yes \u2014 Sample Dealership may email me about vehicles, service and offers. I can unsubscribe from any message."
    }
  ],
  "events": [
    {
      "eventId": "evt_sample-ev-v7-1",
      "tenantId": "sample-dealership",
      "recipientAddress": "riley.okonkwo@sample-buyer.example",
      "summary": "riley.okonkwo@sample-buyer.example asked to be signed up at https://sample-dealership.example/newsletter?list=service-offers\u0026sub=S-23092 on 17 Sep 2026, 18:38 UTC and confirmed 3 minutes later at https://sample-dealership.example/confirm?list=service-offers\u0026sub=S-23092. Whether the link tapped is the link the signup issued is not on record. They agreed to \u0027sample-newsletter-opt-in-dealership-only\u0027 revision 1, held unchanged since 14 Sep 2026, 00:38 UTC. The permission ran to Sample Dealership.",
      "agreedTo": {
        "documentName": "sample-newsletter-opt-in-dealership-only",
        "revision": 1,
        "revisionsOnRecord": 1,
        "heldSince_observedByRedoubtVault": "2026-09-14T00:38:06.6991471Z",
        "text": "Yes \u2014 Sample Dealership may email me about vehicles, service and offers. I can unsubscribe from any message.",
        "textIs": "the whole text",
        "termsId": "trm_2cacea7fb8c12c058201e75322523b2692f8ead16b8cde184e8a12ec4dfc849c",
        "postedAtUrl_assertedByPlatform": "https://sample-dealership.example/newsletter"
      },
      "occurredAt_assertedByPlatform": "2026-09-17T18:41:03.0000000Z",
      "recordedAt_observedByRedoubtVault": "2026-09-17T18:41:04.1490385Z",
      "method": "double-opt-in",
      "source": "https://sample-dealership.example/confirm?list=service-offers\u0026sub=S-23092",
      "linkSignature_assertedByPlatform": "1301115e0174fd1662f39311282bb6ee3ceb3ae36c80d3bf06e9124ffe0284e8",
      "listId_assertedByPlatform": "service-offers",
      "subscriberId_assertedByPlatform": "S-23092",
      "cameFrom_assertedByPlatform": {
        "source": "email",
        "medium": "email",
        "campaign": "double-opt-in-confirmation",
        "placement": "confirm-link",
        "offer": "Free tire rotation with an oil change",
        "device": "mobile"
      },
      "consentTermsRef": "trm_2cacea7fb8c12c058201e75322523b2692f8ead16b8cde184e8a12ec4dfc849c",
      "channel": "email",
      "permissionRanTo_assertedByPlatform": [
        "Sample Dealership"
      ],
      "howThisReachedUs": "reported as it happened \u2014 the platform sent this to Redoubt Vault 1.1 seconds after the moment it gives. We hold the platform\u0027s report from then on; we did not see the act itself.",
      "confirmationOfASignupWeHold": {
        "requestId": "sample-req-v7-1",
        "theSignup": {
          "requestedAt_assertedByPlatform": "2026-09-17T18:38:03.0000000Z",
          "recordedAt_observedByRedoubtVault": "2026-09-17T18:38:03.7174128Z",
          "source": "https://sample-dealership.example/newsletter?list=service-offers\u0026sub=S-23092",
          "linkSignature_assertedByPlatform": "f5e09550287b599f8b26fbe9584ebe8a0fd973f283daffadd56007aaf5b9bfc7",
          "confirmationLinkSignature_assertedByPlatform": "not sent \u2014 the signup did not say which confirmation link it issued",
          "listId_assertedByPlatform": "service-offers",
          "subscriberId_assertedByPlatform": "S-23092",
          "cameFrom_assertedByPlatform": {
            "source": "facebook",
            "medium": "paid-social",
            "campaign": "fall-service-special",
            "placement": "reel",
            "offer": "Free tire rotation with an oil change",
            "device": "mobile"
          },
          "consentTermsRef": "trm_2cacea7fb8c12c058201e75322523b2692f8ead16b8cde184e8a12ec4dfc849c",
          "permissionRanTo_assertedByPlatform": [
            "Sample Dealership"
          ],
          "mechanism_assertedByPlatform": {
            "checkboxPreTicked": false,
            "scrollRequired": false,
            "confirmationMessageId": "\u003Cconfirm-S-23092@mail.sample-dealership.example\u003E",
            "signupUrl": "https://sample-dealership.example/newsletter?list=service-offers\u0026sub=S-23092",
            "unsubscribeMechanism": "List-Unsubscribe one-click"
          }
        },
        "betweenTheTwoActs": {
          "humanReadable": "3 minutes",
          "reading": "typical of a person confirming as soon as the email arrived",
          "iso8601Duration": "PT3M"
        },
        "sameListAndSubscriberOnBoth": "yes \u2014 both acts name the same list and the same subscriber",
        "confirmationCameFromTheLinkTheSignupIssued": "not comparable \u2014 the signup did not say which confirmation link it issued, so nothing ties the confirmation\u0027s link to the one issued",
        "theSameWordingOnBoth": "yes \u2014 the signup form and the confirmation pinned the same text",
        "signupOnRecordBeforeTheConfirmation": "yes \u2014 Redoubt Vault recorded the signup before the confirmation happened",
        "whatThisMeans": "two separate acts, each with its own link, its own time and its own record of what it showed. Redoubt Vault held the signup before the confirmation happened. We did not witness anyone clicking either one: both remain the platform\u0027s assertions. What is checked is that the first act was on a record nobody can edit before the second took place, which is materially harder to produce after the fact than the words \u0027double-opt-in\u0027 in a method field."
      },
      "attestation_assertedByPlatform": "none \u2014 an observed record needs no attestation, and an imported one cannot be recorded without it",
      "mechanism_assertedByPlatform": {
        "checkboxPreTicked": false,
        "scrollRequired": false,
        "confirmationMessageId": "\u003Cconfirm-S-23092@mail.sample-dealership.example\u003E",
        "signupUrl": "https://sample-dealership.example/newsletter?list=service-offers\u0026sub=S-23092",
        "collectedAt": "2026-09-17T18:38:03.0000000Z",
        "unsubscribeMechanism": "List-Unsubscribe one-click"
      }
    },
    {
      "eventId": "evt_sample-ev-v8-1",
      "tenantId": "sample-dealership",
      "recipientAddress": "riley.okonkwo@sample-buyer.example",
      "summary": "riley.okonkwo@sample-buyer.example asked to be signed up at https://sample-dealership.example/newsletter?list=service-offers\u0026sub=S-23092 on 22 Sep 2026, 02:23 UTC and confirmed 3 minutes later at https://sample-dealership.example/confirm?list=service-offers\u0026sub=S-23092. The link tapped is the link the signup issued. They agreed to \u0027sample-newsletter-opt-in-dealership-only\u0027 revision 1, held unchanged since 14 Sep 2026, 00:38 UTC. The permission ran to Sample Dealership.",
      "agreedTo": {
        "documentName": "sample-newsletter-opt-in-dealership-only",
        "revision": 1,
        "revisionsOnRecord": 1,
        "heldSince_observedByRedoubtVault": "2026-09-14T00:38:06.6991471Z",
        "text": "Yes \u2014 Sample Dealership may email me about vehicles, service and offers. I can unsubscribe from any message.",
        "textIs": "the whole text",
        "termsId": "trm_2cacea7fb8c12c058201e75322523b2692f8ead16b8cde184e8a12ec4dfc849c",
        "postedAtUrl_assertedByPlatform": "https://sample-dealership.example/newsletter"
      },
      "occurredAt_assertedByPlatform": "2026-09-22T02:26:26.0000000Z",
      "recordedAt_observedByRedoubtVault": "2026-09-22T02:26:26.9683122Z",
      "method": "double-opt-in",
      "source": "https://sample-dealership.example/confirm?list=service-offers\u0026sub=S-23092",
      "linkSignature_assertedByPlatform": "1301115e0174fd1662f39311282bb6ee3ceb3ae36c80d3bf06e9124ffe0284e8",
      "listId_assertedByPlatform": "service-offers",
      "subscriberId_assertedByPlatform": "S-23092",
      "cameFrom_assertedByPlatform": {
        "source": "email",
        "medium": "email",
        "campaign": "double-opt-in-confirmation",
        "placement": "confirm-link",
        "offer": "Free tire rotation with an oil change",
        "device": "mobile"
      },
      "consentTermsRef": "trm_2cacea7fb8c12c058201e75322523b2692f8ead16b8cde184e8a12ec4dfc849c",
      "channel": "email",
      "permissionRanTo_assertedByPlatform": [
        "Sample Dealership"
      ],
      "howThisReachedUs": "reported as it happened \u2014 the platform sent this to Redoubt Vault 1 second after the moment it gives. We hold the platform\u0027s report from then on; we did not see the act itself.",
      "confirmationOfASignupWeHold": {
        "requestId": "sample-req-v8-1",
        "theSignup": {
          "requestedAt_assertedByPlatform": "2026-09-22T02:23:25.0000000Z",
          "recordedAt_observedByRedoubtVault": "2026-09-22T02:23:26.4616013Z",
          "source": "https://sample-dealership.example/newsletter?list=service-offers\u0026sub=S-23092",
          "linkSignature_assertedByPlatform": "f5e09550287b599f8b26fbe9584ebe8a0fd973f283daffadd56007aaf5b9bfc7",
          "confirmationLinkSignature_assertedByPlatform": "1301115e0174fd1662f39311282bb6ee3ceb3ae36c80d3bf06e9124ffe0284e8",
          "listId_assertedByPlatform": "service-offers",
          "subscriberId_assertedByPlatform": "S-23092",
          "cameFrom_assertedByPlatform": {
            "source": "facebook",
            "medium": "paid-social",
            "campaign": "fall-service-special",
            "placement": "reel",
            "offer": "Free tire rotation with an oil change",
            "device": "mobile"
          },
          "consentTermsRef": "trm_2cacea7fb8c12c058201e75322523b2692f8ead16b8cde184e8a12ec4dfc849c",
          "permissionRanTo_assertedByPlatform": [
            "Sample Dealership"
          ],
          "mechanism_assertedByPlatform": {
            "checkboxPreTicked": false,
            "scrollRequired": false,
            "confirmationMessageId": "\u003Cconfirm-S-23092@mail.sample-dealership.example\u003E",
            "signupUrl": "https://sample-dealership.example/newsletter?list=service-offers\u0026sub=S-23092",
            "unsubscribeMechanism": "List-Unsubscribe one-click"
          }
        },
        "betweenTheTwoActs": {
          "humanReadable": "3 minutes",
          "reading": "typical of a person confirming as soon as the email arrived",
          "iso8601Duration": "PT3M1S"
        },
        "sameListAndSubscriberOnBoth": "yes \u2014 both acts name the same list and the same subscriber",
        "confirmationCameFromTheLinkTheSignupIssued": "yes \u2014 the confirmation carries the signature of the link the signup issued: the link tapped is the link issued, and the signup committed to it before the tap",
        "theSameWordingOnBoth": "yes \u2014 the signup form and the confirmation pinned the same text",
        "signupOnRecordBeforeTheConfirmation": "yes \u2014 Redoubt Vault recorded the signup before the confirmation happened",
        "whatThisMeans": "two separate acts, each with its own link, its own time and its own record of what it showed. Redoubt Vault held the signup before the confirmation happened. We did not witness anyone clicking either one: both remain the platform\u0027s assertions. What is checked is that the first act was on a record nobody can edit before the second took place, which is materially harder to produce after the fact than the words \u0027double-opt-in\u0027 in a method field."
      },
      "attestation_assertedByPlatform": "none \u2014 an observed record needs no attestation, and an imported one cannot be recorded without it",
      "mechanism_assertedByPlatform": {
        "checkboxPreTicked": false,
        "scrollRequired": false,
        "confirmationMessageId": "\u003Cconfirm-S-23092@mail.sample-dealership.example\u003E",
        "signupUrl": "https://sample-dealership.example/newsletter?list=service-offers\u0026sub=S-23092",
        "collectedAt": "not sent \u2014 the platform did not say when the form was submitted",
        "unsubscribeMechanism": "List-Unsubscribe one-click"
      }
    }
  ],
  "howToRead": {
    "timestamps": "occurredAt is the platform\u0027s assertion of when consent happened; Redoubt Vault records this claim as a claim. recordedAt is when Redoubt Vault observed the event being recorded. From that moment the record is append-only: it cannot be edited or deleted through any API, and the service\u0027s own credentials carry no permission to modify it. Every timestamp in this packet is UTC, to the same precision, so two of them can be compared by eye. What the gap between occurredAt and recordedAt means is stated per event under howThisReachedUs.",
    "howThisReachedUs": "howThisReachedUs says how each event came to be on record, in one of three states. Reported as it happened: the platform sent it to Redoubt Vault within 24 hours of the moment it gives. Reported late: it arrived more than 24 hours after that moment, up to 7 days, and nothing about it was on record with us in between. Imported: history from the platform\u0027s own records, sent to Redoubt Vault long after the fact, with the name of the person who put their name to it. In every state Redoubt Vault holds the platform\u0027s report from the moment it arrived; it never saw the act itself. An event that predates provenance tracking says so and claims none of the three.",
    "absences": "Every value the platform did not send reads as a sentence beginning \u0022not sent\u0022. There are no blanks and no nulls: a blank would read as a field we forgot, and a null cannot say whether the platform sent nothing or sent nothing on purpose. What the platform did not record, this packet says it did not record.",
    "summaryAndAgreedTo": "Each event opens with summary, one plain reading of the record beneath it, and agreedTo, the wording the person agreed to, quoted from the consentTerms section with its revision and the date it was first held. Neither adds a claim: both restate what the event and the terms already record, in the same asserted-by-the-platform and observed-by-Redoubt-Vault terms.",
    "consentTerms": "An event\u0027s consentTermsRef points into the consentTerms section, which embeds the exact text the platform asserts was presented at consent. The platform\u0027s assertion is a claim; what Redoubt Vault attests is narrower and stronger: this exact text (its identifier is its own SHA-256) has been held unmodified since heldSince. An event marked as having no terms captured was recorded without a terms reference; this packet claims nothing about what that recipient was shown.",
    "doubleOptIn": "A signup and its confirmation are two separate acts, and both are here. The event is the confirmation: its own occurredAt, its own source link, its own consentTermsRef. Nested inside it under confirmationOfASignupWeHold is theSignup, the first act, with the link it was collected at, when the platform says it happened, when we recorded it, and the wording that form showed at that time. betweenTheTwoActs states the interval outright: a confirmation seconds after a signup, or a year after, are both worth asking about, and that is the reader\u0027s judgment.",
    "linkSignatures": "linkSignature is the SHA-256 of the token in each act\u0027s link, as the platform sent it. We never receive the token, because it works like a password, so we cannot check it against the link. What it fixes is that the platform committed to one specific link for this person, at the time, in a record it cannot edit afterwards. confirmationLinkSignature, on theSignup, is the SHA-256 of the token in the confirmation link the signup issued, sent at signup time, before anyone could tap it. confirmationCameFromTheLinkTheSignupIssued compares it with the confirmation\u0027s own linkSignature: yes means the link tapped is the link issued, and the signup committed to that link on a record nobody can edit before the tap.",
    "confirmationMessageId": "confirmationMessageId, inside mechanism, is the platform\u0027s mail provider\u0027s own id for the confirmation email. It lets the platform produce that provider\u0027s delivery and click record for the message. We hold the id, not the record.",
    "collectedAt": "collectedAt, inside mechanism, is when the platform says the form was submitted. A confirmation that names a signup is refused one, because the signup\u0027s own time already says it. An older confirmation may still carry one; where it does, it repeats the signup\u0027s time and is not a second time for the confirmation.",
    "listSubscriberAndOrigin": "listId and subscriberId are the platform\u0027s own identifiers for the list the act was for and the person it was for, and cameFrom is where the signup came from: source, medium, campaign, placement, the offer, and the kind of device. All asserted by the platform, none checked by us, and never an IP address or user agent. sameListAndSubscriberOnBoth says whether the two acts name the same list and subscriber.",
    "wordingOnBoth": "theSameWordingOnBoth says whether the form and the confirmation pinned the same text. Where they differ, both texts are in the consentTerms section in full; neither was retrofitted onto the other.",
    "signupOnRecordFirst": "signupOnRecordBeforeTheConfirmation says whether Redoubt Vault recorded the signup before the moment the platform says the confirmation happened. Yes means the first act sat on a record nobody can edit before the second took place. No means both acts reached us afterwards, and their order is the platform\u0027s word alone.",
    "whatADoubleOptInEstablishes": "The signup was on record before the confirmation was written, because Redoubt Vault refused to record the confirmation unless we were already holding the request. It does not establish that any human clicked either one; we never receive the click, by design, and both acts stay the platform\u0027s assertions. An event naming no signup request is a single opt-in or predates this record shape: a different thing from a double opt-in, not a worse version of one. The exception is an event whose method still calls it a double opt-in: the packet says so beside it, because the signup that word implies is then missing from the record.",
    "suppressions": "A suppression records that this recipient unsubscribed. It sits in its own chain, parallel to the consent events and never modifying them: \u0022consented in March, unsubscribed in June\u0022 is two records in time order, not one record that changed. A consent event dated after a suppression is presented as it stands, without editorial. A suppression records when the platform was asked to stop, and when it told us. A suppression that names a list (listId_assertedByPlatform) is a withdrawal from that list only, as the platform told us: the person\u0027s consent to any other list on this tenant stands as recorded, and a consent that names no list is not read as belonging to it. A suppression that names no list covers the whole tenant. Signup requests are not in this packet\u0027s events: an unconfirmed signup is not consent.",
    "erasedOnRequest": "A record whose recipientAddress reads \u0022erased on request\u0022 belongs to a person the platform asked us to forget. The record itself is exactly as it was written; only the link from it to the person\u0027s address has been removed, so nobody, including us, can say whose it was. It was erased; it was not \u0022never consented\u0022."
  }
}